PMS 1.21.0.3616 allows unauthorized and usecure access to Plex VOD Movies

Server Version#: 1.21.0.3616

I’ve just noticed that my PMS allows direct access to the Plex VOD stuff
when accessing http(s)://serverip:32400 directly

how can I block that?

anyone can access this and watch the VOD stuff
there is no access to my librarys but I still want to disable this
plays through that are not even logged in tautulli

What do you mean by directly? Are you not prompted for a pin or anything when accessing the network IP for your server?

that’s exactly what I mean
I even tried it in a new incognito window
it does not prompt for anything
neither through http nor https

I’ve set secure connections to required
now at least http cannot be accessed anymore
still the same on https though
no access limitation there

There are another couple threads discussing this. I can find 'em if you like.

In a recent change, every Plex Media Server installed now gives remote and anonymous users access to the same free Movies, TV, and other content as http://plex.tv/.

In a recent change, every Plex Media Server installed now gives remote and anonymous users access to the same free Movies, TV, and other content as http://plex.tv/.

so what, are you saying this is intended?

what the hell

I mean it does not really impact anything, it doesn’t even create noticeable traffic
but still
I don’t want that

why is that even enabled?
are they just using our servers as an extension for their network?
in case plex.tv goes down?
what’s the purpose of this

Yes. To say that I’m not a fan is putting it mildly.

Content isn’t streamed from your system. But the perception is very bothersome.

I can’t even diable this for my shared users
and now they enabled it for everyone

what the actual f

so that’s what we pay for?
unwanted and unnecessary features we can’t even disable…

sadly only 7 votes on your feature request
we need to spread the word :wink:

While I shouldn’t be sticking my toes in this fishbowl …

  1. Management is aware of the perception being created. They had not anticipated it.
  2. At last word they are rethinking this mechanism.
  3. It was done as a way to give more people easy access to free content in the light of COVID restricting everyone’s activities.

I am going to ask you all to focus your comments on the other pre-existing threads & feature requests.

Having multiple threads like this one, of which there are many, only dilute the message.

I will wait 5 minutes before closing this thread in favor of those other duplicate threads.

1 Like

You can hide the “on Plex” content for yourself, when logged in, and for any managed users, because those are part of your account.

You can’t hide the “on Plex” content for users you share your content with, because you don’t own those users or the “on Plex” content - it’s not coming from your server. They’re using independent Plex accounts, who may also have their own servers, or access to multiple other servers. They’re grown-ass adults and can choose to hide the “on Plex” if they wish.

And that all makes sense to me. I understand that people think of users they share with as “their” users, but they aren’t.

But that’s completely orthogonal to what the Plex Web app does when it’s loaded from my server. Offering the “on Plex” content to anonymous remote users is … inappropriate.

That’s fair feedback, and thank you.

Would you mind sharing the same “there is internal discussion about this” feedback on those other threads?

You are free to quote me.

1 Like